ANUGAL UAC SERIES · 3 OF 6 · RISK STORY
Toxic Access Combinations: How One Role Change Creates Them
Meet Arun. Today he moved from operations to finance. The role change processed in seconds, and his new access arrived instantly. Nobody removed the old access from a job he no longer has.
Each entitlement looks harmless on its own. Together, they let one identity approve finance transactions, process refunds, and approve the vendors being paid. Risk level: critical. And the quarterly review that should catch it arrives as a spreadsheet, one row among hundreds, no context, no history. Approved by default.
THE SHORT ANSWER
A toxic access combination forms when entitlements that are safe alone become dangerous together, most often after a role change leaves old access in place. Segregation-of-duties checks inside the certification, recertification triggered by movement, and automatic revocation of retained access close the gap before an auditor or an attacker finds it.
Why are movers riskier than joiners or leavers?
Joiners get scrutiny: a request, an approval, a start date. Leavers get offboarding: HR ends the record and deprovisioning follows. Movers get neither. The new manager requests the new access and owns it. The old access belongs to a job that no longer exists, which means it belongs to nobody, which means it stays.
Scale that across a large enterprise running thousands of internal moves a year, and access accumulates silently in exactly the population auditors sample. Segregation-of-duties conflicts remain among the highest-risk areas auditors flag in ITGC testing.
Joiners get scrutiny, leavers get offboarding; movers get both jobs' access and neither job's review.
Why does the quarterly review miss it?
Three reasons, and the calendar is only one of them. First, timing: a January move waits for a March campaign, and the toxic combination lives for a quarter. Second, presentation: the reviewer sees rows per system, and a conflict that spans systems is invisible in any single row. Third, context: with no access history on screen, retained access from the old role looks identical to access that belongs.
The conflict is invisible in any single row; it lives in the combination.
So catching it is not a matter of reviewing harder. It is a matter of reviewing differently.
What does catching it in time look like?
- SoD checks inside the certification. Conflicting combinations highlight in the review context itself, across systems, at the moment of decision.
- Recertification triggered by movement. Role and organizational change starts a scoped review of that mover, instead of waiting for the calendar.
- Dormant and excess access flagged proactively. Unused and overlapping access from the old role surfaces before anyone asks.
- Risk-tier campaigns. Movers and high-privilege identities get closer, more frequent review than stable populations.
- Enforcement on decision. The revoke executes automatically, so the retained access leaves.
Catch the combination at the moment of movement, not at the quarter's end.
The Mover Checklist: 5 controls for every role change
THE MOVER CHECKLIST
- Trigger a scoped micro-review on every move, covering only the mover.
- Compare old-role and new-role access side by side, not as one merged list.
- Run segregation-of-duties checks across the combined access, never per system.
- Time-box any access deliberately retained, with an expiry date and a named owner.
- Log the rationale for whatever stays, so the next review starts with history.
Mistakes that keep the mover problem alive
- Assuming JML automation handles it. Lifecycle automation grants the new access reliably; removing the old is the part that gets skipped.
- Reviewing only the new access. The request workflow scrutinizes what was asked for. The risk sits in what was never asked about.
- Running SoD per application. Arun's conflict spans systems. Per-app checks each report a clean bill.
Frequently asked questions
What is a toxic access combination?
A set of entitlements that are individually legitimate but together break segregation of duties, for example one identity that creates vendors, approves payments, and processes refunds. The danger sits in the combination, which is why per-system reviews miss it.
What is access creep?
The gradual accumulation of access as people change roles, join projects, and cover absences without old permissions being removed. Left unreviewed, long-tenured employees end up with the widest access and the least oversight, exactly the profile attackers and auditors both look for.
Should a role change trigger an access review?
Yes. Movement is the highest-risk identity event because it combines two jobs' access in one person. A scoped recertification at the moment of movement, aligned to role and organizational change, closes the window that calendar-based campaigns leave open.
How Anugal solves it
The video above ends where this section begins: with the whole problem visible in one place.
HOW ANUGAL SOLVES IT
- Sees what spreadsheets miss. The role change, the retained access, and the SoD conflict, surfaced together with a recommended action on each risk.
- Approval where the manager already works. The decision lands in Microsoft Teams, with no new system to learn.
- One pass, both directions. Agentic AI analyzes every line: approve the new finance access and revoke what was retained, in a single motion.
- Certified, revoked, logged. Enforcement executes automatically and every decision writes to the audit trail on its own.
- Movement-aware by design. Recertification aligns to role and organizational change, and dormant or excess access flags proactively (per Anugal's UAC materials).
About Anugal. Anugal is the Agentic Identity Governance and Administration platform from Business Core Solutions (BCS). It orchestrates identity lifecycle, access requests, certifications, and risk governance across the enterprise, with 350+ integrations through SCIM 2.0, REST APIs, OData, SOAP, SAP ABAP, and SQL.
SEE IT ON YOUR OWN CAMPAIGN DATA
Bring one recent certification export and we will show you what Anugal UAC surfaces in it: the risk, the rubber-stamps, and the revocations that never executed.
hello@businesscoresolutions.com
Next in this series is live: Access Revocation: Why Certified Removals Never Happen
